The focused artifact has a usable README, a clear MIT license, and no install-time scripts. Limited project hygiene and the single-person backing provide little evidence of support if compatibility problems arise.
42%
Total Score
25
63
75
The package has had no release in more than five years, and releases_last_12_months is 0. This is strong evidence of abandonment risk despite its earlier release history.
The repository recorded 0 commits and 0 active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but that does not demonstrate current maintenance.
Only one registry account has publish access. The linked repository is owned by a user rather than an organization, so there is little visible maintainer redundancy.
The repository has no security policy. For a small deployment recipe this is a transparency gap, though it is less significant than the lack of recent maintenance.
The assessed release is v7.0.0-beta1, so consumers are taking a dependency on a prerelease rather than a stable release. The small recent prerelease share provides little compensation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
deployer/deployer Version >=7.0-beta | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.